Repository navigation
evidence(OMN-14888): OCC observation append (38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml) - #6152
Merged
Merged
Conversation
added 2 commits
August 6, 2026 06:59
…niNode-ai__omnimarket/pr-2024/38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml
jonahgabriel
force-pushed
the
auto/occ-observation-drift-occ-observations-omninode-ai--omnimarket-pr-2024-38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8--v1--run31062523818-1-yaml
branch
from
August 6, 2026 11:02
79befab to
c8bec95
Compare
jonahgabriel
enabled auto-merge (squash)
August 8, 2026 07:10
# Conflicts: # contracts/OMN-14888.yaml
# Conflicts: # contracts/OMN-14888.yaml
jonahgabriel
deleted the
auto/occ-observation-drift-occ-observations-omninode-ai--omnimarket-pr-2024-38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8--v1--run31062523818-1-yaml
branch
August 9, 2026 07:19
jonahgabriel
added a commit
that referenced
this pull request
Aug 9, 2026
…4994a03a479ac90f__v1__run31292255084-1.yaml) (#6240) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/2cea83b3d664a5a3a919d4e14994a03a479ac90f__v1__run31292255084-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31292255084-1 * evidence(OMN-15763): OCC companion for omnimarket PR #2027 (#6239) * evidence(OMN-15763): OCC companion for omnimarket PR #2027 Falsifiable deploy-gate evidence (OMN-14505 sense) for the seam registry + canonical seam-projection serialization PR: three live GitHub-content probes against the PR head commit (canonical.py's canonical_sha256, node_seam_match_compute's HandlerSeamMatch, and seams.v1.yaml's schema_version header), plus the standard self-bind check. All three probes verified locally against the PR head SHA 6bbd87de3c0173956969f5a0b159c8631e4b929e before committing. Rebuilt on origin/dev (onex_change_control's live default branch — main now accepts only promotion/hotfix PRs, discovered live via main-target-guard on the first attempt against main). Net-new-file-only. OMN-15763 * fix(OMN-15763): buffer check_value producers to avoid Rule E SIGPIPE false-RED OMN-15411 Rule E (contract corpus ratchet) caught 3 new sigpipe-fragile instances: gh api <contents> --jq .content | base64 -d | grep -q ... is a measured SIGPIPE-fragile shape (141/0/141/0/141 across 5 runs against real inputs) — grep -q exits at the first match and closes its stdin, base64 -d is killed by SIGPIPE, and dod_verify's bash -o pipefail turns that 141 into a false RED on evidence that is actually present. Rewrote all three live-content probes to the buffered-read form: body="$(<producer>)" && printf '%s' "$body" | grep -qF 'MARKER'. Verified locally: sigpipe_fragile_violation() returns None for all three (was non-None before), all three still execute correctly under bash -o pipefail -c against the live GitHub API, and validate_pr_deploy_required.has_deploy_evidence() still returns True (the buffered form still classifies as a falsifiable live-surface probe). Also re-pinned all three refs to the omnimarket PR's final head commit f1741be0163ab757738bb9ddbf7d2d67aca6aa49 (was 6bbd87de, superseded by the CodeRabbit-fix commit). OMN-15763 * evidence(OMN-15763): PASS receipts for all four dod_evidence items occ-preflight/verify hard-required receipts under drift/dod_receipts/OMN-15763/<item_id>/command.yaml for every item -- an OCC PR's in-tree contract carries its own receipts (the "in-repo trap"). All four probes run for real against the omnimarket PR #2027 head commit f1741be0163ab757738bb9ddbf7d2d67aca6aa49 and this OCC PR's own state (#6239). contract_sha256 + contract_entry_sha256 computed via omnibase_core.validation.validator_receipt_gate against the landed contract (commit 5f647f0). Verified locally end-to-end: uv run python -m omnibase_core.validation.validator_occ_merge_eligibility against this tree returns eligible=true, reason=eligible, zero missing_or_nonpass_receipts. probe_stdout required a non-empty value (ModelDodReceipt: "receipts with empty stdout are indistinguishable from probes that never ran") -- the contract's check_value stays the buffered grep -qF form (Rule E safe, quiet by design), while each receipt's own probe_command is the non-quiet grep -F variant that captures the actual matched line as real evidence. OMN-15763 * evidence(OMN-14888): OCC observation append (b8a1eb65a20f32e0e00efd473aaf7b69f3cad6f9__v1__run31058937953-1.yaml) (#6144) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/b8a1eb65a20f32e0e00efd473aaf7b69f3cad6f9__v1__run31058937953-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31058937953-1 * evidence(OMN-14888): self-bind OCC observation PR 6144 * evidence(OMN-14888): make OCC self-bind 6144 append-stable * fix(OMN-14888): repair self-bind assertion in occ-self-bind-pr-6144 Rewrite the dod_evidence check to bind PR #6144 to immutable facts (PR number, base repo, exact head ref) and accept state open OR closed+merged, so the check stays true after this PR merges instead of asserting .state == "open" forever. * fix(OMN-14888): regenerate occ-self-bind-pr-6144 receipt for repaired check_value Bind contract_entry_sha256 to the updated dod_evidence entry hash so the OCC merge-eligibility gate's per-entry binding check passes. * fix(OMN-14888): supersede occ-self-bind-pr-6134 with merged-terminal-state binding PR #6134 merged to dev (2026-08-09T03:14:53Z, ea53c31) while this PR was in flight. Its self-bind entry asserts .state == "open" forever, which now fails closed. Append-only supersession per the occ-self-bind-pr-5855-superseded / occ-self-bind-pr-6149-superseded precedent — bind to the merged-terminal state instead; the superseded entry stays verbatim for audit. --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (7bd1c1a9c39823834fe4e38dabc785887ecf524c__v1__run31054912492-1.yaml) (#6132) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2021/7bd1c1a9c39823834fe4e38dabc785887ecf524c__v1__run31054912492-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31054912492-1 * evidence(OMN-14888): self-bind OCC observation PR 6132 * evidence(OMN-14888): make OCC self-bind 6132 append-stable * fix(OMN-14888): regenerate occ-self-bind-pr-6132 receipt for entry-hash match The contract entry's check_value was rewritten to accept open OR closed+merged terminal state (self-bind fix), which changed its recomputed contract_entry_sha256. Regenerated the receipt with a fresh live probe against PR #6132 and the matching entry hash so occ-preflight eligibility passes instead of failing on contract_hash_mismatch. --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * fix(OMN-15722): raise starved guard-job timeout budgets in OCC ci.yml (#6173) * fix(OMN-15722): raise starved guard-job timeout budgets in OCC ci.yml Five guard jobs carry timeout-minutes budgets below the observed latency of the self-hosted omnibase-ci runner fleet under concurrent load. When a job hits its own timeout wall GitHub records conclusion=cancelled, and CI Summary (the sole required umbrella context on onex_change_control dev) compares each needs.<job>.result against "success" fail-closed - so a guard that passed gets scored as a violation and turns the required context red. Raise the three 5-minute guards and the two 10-minute jobs to 20 minutes: - validate-prod-promotion-grants 5 -> 20 - check-platform-leads-review-tripwire 5 -> 20 - check-bot-authored-authz-guard 5 -> 20 - predicate-parity 10 -> 20 - no-noncanonical-lifecycle-classes 10 -> 20 Not a gate weakening: every guard still runs, still must reach conclusion=success, and CI Summary's fail-closed != "success" comparison is untouched. Only the wall-clock budget moved. Evidence-Ticket: OMN-15722 * evidence(OMN-15722): add OCC ticket contract + PASS receipts for guard timeout fix The first push carried no contracts/OMN-15722.yaml, so both of the two content-gating required contexts on this PR failed with the same single root cause: validator_occ_merge_eligibility reported reason=missing_contract / missing_contracts=["OMN-15722"] on `occ-preflight / eligibility` (job 93010633789) and on `verify / verify` step 21 "Run OCC Eligibility" (job 93010633875). Note step 7 "Resolve Evidence-Source" was SKIPPED in that same job, confirming the in-repo Evidence-Source exemption - the missing contract was the only blocker. Contract declares three dod_evidence items, all probed live and receipted with real command output (no fabricated receipts): dod-occ-guard-timeout-budgets-raised - substantive (L1): parses ci.yml and asserts all five named guard jobs declare timeout-minutes 20. dod-occ-guards-still-fail-closed - substantive (L1): asserts all five guards remain in ci-summary's needs list, carry no continue-on-error, still have their literal fail-closed `result }}" != "success"` comparison in ci.yml, and that ci.yml still declares no top-level concurrency block. Falsifiability proven by negative control - rewriting the predicate-parity comparison to an equality form makes the same probe exit 1 with unguarded=['predicate-parity']. occ-self-bind-pr-6173 - binding stamp only (L0), companion PR identity for receipt-gate binding. Local verification: all three probes exit 0 / stdout "true"; the eligibility validator now returns eligible=true reason=eligible ("OCC evidence is present, PASS, hash-bound, and PR-bound") with all three receipt ids resolved. Full pre-commit over contract + receipts + ci.yml passes, including Receipt Honesty Gate, Receipt Hardening Gate, Contract Substance Floor, DoD-authoring hygiene, Canonical contract shape v1, and the Evidence-Commit SHA Existence Gate. Evidence-Ticket: OMN-15722 * evidence(OMN-15722): remove false no_source_change attestation from receipts All three OMN-15722 receipts asserted no_source_change: true. Per omnibase_core model_dod_receipt.py that field is RUNTIME_OPS-only and asserts the change produced NO repo diff and NO PR. This change has a 5-line ci.yml diff and IS PR #6173, so the assertion was materially false. These receipts carry evidence_class: None and pr_number: 6173, so the field does not apply to them at all -- removed rather than set to false. Its default is False, which is the truthful value. All three re-validate against ModelDodReceipt with no_source_change=False. Note: the model validator enforces only the RUNTIME_OPS -> True direction, not the inverse, so a non-RUNTIME_OPS receipt asserting no_source_change: true alongside a pr_number validates cleanly and no CI gate would have caught this. Model gap, flagged not fixed here. * fix(OMN-15722): widen validate-prod-promotion-grants budget to 45m (19m02s measured) The 20m budget left that job ~58s of headroom against its measured 19m02s runtime on PR #6173 run 31222755192 — a re-starve one contention spike away, which is the exact defect this PR exists to remove. Profile of the 19m02s (steps API, head 2df62fc): Checkout code 11m48s Run ./.github/actions/setup-uv 5m30s Validate prod-promotion-grants trust anchor 2s The work is 2 seconds; the runtime is fleet latency. Within that one run, Checkout code for the same repo/SHA ranged 74s (omninode-runner-63) to 708s (omninode-runner-21) — a ~9.6x contention spread — so the budget must cover the latency tail, not the job's work. 45m is ~2.4x the worst observation. Other four guards unchanged at 20. Contract probe updated from a flat ==20 assertion to a per-job expected-budget map so it stays falsifiable, and the contract summary corrected (it claimed all five go to 20). * evidence(OMN-15722): re-stamp all three receipts at head d772fb8 The prior stamps carried run_timestamp 2026-08-07T22:29:26Z / commit_sha 2df62fc, which predated both the 45m widening and the contract edit — the receipts attested a tree that no longer existed. All three probes were re-run against the working tree at d772fb8; none of these values is carried over: dod-occ-guard-timeout-budgets-raised exit 0, stdout 'true' dod-occ-guards-still-fail-closed exit 0, stdout 'true' occ-self-bind-pr-6173 exit 0, stdout 'true' Receipt 1's probe changed with the contract: a flat 'all five == 20' assertion would now fail, so it became a per-job expected-budget map (45/20/20/20/20). Its contract_entry_sha256 is recomputed to sha256:4c1ae3b62a7def4f0ca209d9921d974c6c74a4927cb8dc5fa3d4e32a99adeec8; entries 2 and 3 are parse-identical so their hashes are unchanged. Both substantive probes re-verified falsifiable at this head by negative control — reverting 45->20 exits 1 with [('validate-prod-promotion-grants', 20, 45)], and flipping the predicate-parity comparison to == exits 1 with unguarded=['predicate-parity']. * fix(OMN-15722): uniform 45m timeout floor across all 10 budgeted ci-summary needs members contract-shape-v1 (budget 25) was cancelled at 25m50s on this PR's own run 31222755192, cancelled step Checkout code (1358s) - the same starvation the five already-raised guards hit. Inside that one run, for the same repo and SHA, checkout ranged 6s-1358s and setup-uv 93s-571s, so the runner preamble alone has been observed above 30m and every per-job budget under that is provably insufficient. Sets 45 uniformly across all ten ci-summary needs members that declare a timeout-minutes. Also corrects the inline fleet-size comment: live gh api orgs/OmniNode-ai/actions/runners reports 64 runners labelled omnibase-ci, not 48. * evidence(OMN-15722): re-stamp all three receipts at the uniform-45m head * docs(OMN-15722): tighten the latency claim to single-phase observations The prior wording said the runner preamble had been observed above 30m; that number was a cross-job sum of the worst checkout (1358s, contract-shape-v1) and the worst setup-uv (571s, a different job), not a single observed preamble. Replaced with the two exact single-phase observations plus the worst own-work step among the ten budgeted gates (53s). No budget changes. * evidence(OMN-15722): re-stamp all three receipts at 63be7d6 * evidence(OMN-15722): admissible self-bind supersedes gh-pr-view INERT check occ-self-bind-pr-6173 uses `gh pr view`, which lexes to bare `gh` in command position (not `gh api`) and is INADMISSIBLE (NOT_EXECUTED) under the OMN-15309 evidence_admissibility predicate. Contract Compliance Check on this PR's own run (31228584791, job 93027660648) collapsed the whole dod_evidence supersession chain to 0/3 PASS -> BLOCK, reddening the required check. Append-only fix: occ-self-bind-pr-6173-admissible supersedes it with `gh api repos/OWNER/REPO/pulls/6173/files` asserting the changed-file count (5), with printed stdout so the run is distinguishable from a probe that never executed (Receipt Hardening Gate, OMN-13060/OMN-15710). Verified ADMISSIBLE by direct execution of classify_evidence over the exact check_value, and the check itself run green (count=5) and red (count=4, exit 1) before being recorded. Nothing above the new entries in contracts/OMN-15722.yaml is edited; every prior dod_evidence item keeps its bytes and OMN-13888 per-entry hash. Local run of scripts/ci/run_contract_compliance_check.py against this head confirms PASS (1/4 PASS, 3 WARN, 0 BLOCK). * evidence(OMN-15722): correct stale self-bind file-count assertion (5 -> 7) occ-self-bind-pr-6173-admissible asserted PR #6173's changed-file count == 5, but adding its own receipt file to the diff made the live count 6 the moment it was committed -- confirmed red on Contract Compliance Check (job 93048702548, run 31236076328): live count=6, assertion expected 5, exit 1. Appends occ-self-bind-pr-6173-admissible-v2, a self-inclusive correction: its own receipt file is the 7th changed path, so it asserts count == 7, the number that includes the file recording its own PASS. * evidence(OMN-15722): OCC companion for #6173 (#6174) * evidence: OCC companion pass 1 for #6173 * evidence: OCC companion self-bind for #6174 * fix(OMN-15722): format OCC autobind contract --------- Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml) (#6149) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31061495853-1 * evidence(OMN-14888): self-bind OCC observation PR 6149 * evidence(OMN-14888): make OCC self-bind 6149 append-stable * fix(OMN-14888): repair PR #6149 self-bind to append-only-stable predicate The occ-self-bind-pr-6149 dod_evidence entry asserted .state == "open", which goes false the instant this PR merges — a self-bind that breaks append-only immutability on merge. Rebind to immutable facts (PR number, base repo, head branch) with state accepted as open OR closed+merged, keeping the check falsifiable for a wrong PR number/branch. * fix(OMN-14888): supersede stale occ-self-bind-pr-6134 open-state assertion PR #6134 merged (2026-08-09T03:14:53Z, merge commit ea53c31...) while its merged dod_evidence entry occ-self-bind-pr-6134 still asserts .state == "open" -- the same class OMN-15374's occ-self-bind-pr-5855-superseded fixed (OCC #6084 precedent). Append a net-new superseding entry bound to the merged-terminal state; the original entry stays untouched (append-only). --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-15763): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2028 (#6242) * evidence(OMN-15763): author OCC companion for OmniNode-ai/omnimarket#2028 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 512b272bb26aba643093872519c8c46c142b0de2. * evidence(OMN-15763): self-bind OCC#6242 + rebind contract_sha256 * fix(OMN-15763): backfill missing dod-occ-evidence-admissibility-validator contract entry The OCC Companion Author automation emitted this receipt on PR #2028's companion (dod-occ-evidence-admissibility-validator, node_pr_lifecycle_fix_effect self-check) without adding the matching dod_evidence contract entry, tripping the receipt-hardening append-only gate. Backfills the entry (source: generated, matching the shape of the other autobind entries) and computes the real contract_entry_sha256 via compute_contract_entry_sha256 (was a "PENDING" placeholder) — verified locally against scripts/validation/check_receipt_hardening.py. OMN-15763 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml) (#6138) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2023/cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31057101391-1 * evidence(OMN-14888): self-bind OCC observation PR 6138 * evidence(OMN-14888): make OCC self-bind 6138 append-stable * fix(OMN-14888): regenerate occ-self-bind-pr-6138 receipt for self-bind fix The self-bind entry's check_value was rewritten to bind to immutable facts (PR#/head ref/base repo, state open OR closed+merged) so the assertion survives merge, matching the #6132/#6144 precedent. This changes contract_entry_sha256, so the receipt is regenerated with the recomputed hash and a fresh live probe readback. --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml) (#6152) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2024/38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31062523818-1 * evidence(OMN-14888): self-bind OCC observation PR 6152 * evidence(OMN-14888): make OCC self-bind 6152 append-stable --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml) (#6164) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2025/d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31142195987-1 --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-15757, OMN-15778): OCC companion for OmniNode-ai/omninode_infra#833 (#6246) * evidence: OCC companion pass 1 for OmniNode-ai/omninode_infra#833 * evidence: OCC companion self-bind for #6246 --------- Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai> * evidence(OMN-15336): bind infra PR 2676 vendor migration (#6167) * evidence(OMN-15336): bind infra PR 2676 vendor migration * evidence(OMN-15336): self-bind OCC PR 6167 * evidence(OMN-15336): refresh registry RLS heads * fix(OMN-15336): supersede market PR 2021 evidence append-only * evidence(OMN-15336): rebind infra PR 2676 current head * chore(OMN-15336): retrigger OCC gates * evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2029 (#6247) * evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2029 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5. * evidence(OMN-15777): self-bind OCC#6247 + rebind contract_sha256 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> * evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2030 (#6248) * evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2030 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 271a7abe276bc6a5663599a6e7736c8faab843f7. * evidence(OMN-15777): self-bind OCC#6248 + rebind contract_sha256 * fix(OMN-15777): revert unintended mutation of merged receipt (append-only repair) The occ-evidence-source-autobind commit for PR #2030 (57e1628) rebound drift/dod_receipts/OMN-15777/dod-occ-evidence-admissibility-validator/command.yaml in place -- but that receipt already merged as part of OCC#6247 (PR #2029's companion) and is immutable per the append-only doctrine. PR #2030 already carries its own dedicated, net-new evidence entries (dod-OmniNode-ai-omnimarket-pr-2030, dod-OmniNode-ai-omnimarket-pr-2030-ci, occ-self-bind-pr-6248) that bind it to commit 271a7abe; the shared validator receipt did not need to be re-pointed at PR #2030 to satisfy that binding. Reverts the file to its merged-on-dev content. No supersession file is needed -- this is not a correction to the receipt's claim (still true and still bound to PR #2029/commit f9cc9dcc), it is an unforced touch that should never have modified it. Implements OMN-15777 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-15780): OCC Evidence-Source autobind for OmniNode-ai/omninode_infra#834 (#6250) * evidence(OMN-15780): author OCC companion for OmniNode-ai/omninode_infra#834 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 1fdeb0c9c9367d70e43ef88b128203cf567c4aed. * evidence(OMN-15780): self-bind OCC#6250 + rebind contract_sha256 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> * evidence(OMN-14888): OCC observation append (023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml) (#6155) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31063872175-1 * evidence(OMN-14888): self-bind OCC observation PR 6155 * evidence(OMN-14888): make OCC self-bind 6155 append-stable * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5__v1__run31303503673-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31303503673-1 * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/c11400fe9483b9face2601c391f0a73add5d52cf__v1__run31304580306-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31304580306-1 * fix(OMN-14888): repair occ-self-bind-pr-6155 receipt after dev-merge Conflict resolution against dev landing on PR #6155 rewrote the occ-self-bind-pr-6155 dod_evidence entry's check_value to accept the terminal closed+merged PR state (matching the occ-self-bind-pr-6134 / occ-self-bind-pr-6149 established pattern) instead of a bare .state == "open" assertion that would fail closed the moment this PR merges. That byte change moved the per-entry contract hash, so the paired receipt is regenerated here with the recomputed contract_entry_sha256 and a fresh live probe_stdout. --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml) (#6237) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31291311120-1 --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> Co-authored-by: onexbot-occ-writer[bot] <307849072+onexbot-occ-writer[bot]@users.noreply.github.com> Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai> Co-authored-by: omnimarket-bot <bot@omninode.ai>
jonahgabriel
added a commit
that referenced
this pull request
Aug 9, 2026
…19c8c46c142b0de2__v1__run31297664660-1.yaml) (#6243) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2028/512b272bb26aba643093872519c8c46c142b0de2__v1__run31297664660-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31297664660-1 * evidence(OMN-15722): OCC companion for #6173 (#6174) * evidence: OCC companion pass 1 for #6173 * evidence: OCC companion self-bind for #6174 * fix(OMN-15722): format OCC autobind contract --------- Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml) (#6149) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31061495853-1 * evidence(OMN-14888): self-bind OCC observation PR 6149 * evidence(OMN-14888): make OCC self-bind 6149 append-stable * fix(OMN-14888): repair PR #6149 self-bind to append-only-stable predicate The occ-self-bind-pr-6149 dod_evidence entry asserted .state == "open", which goes false the instant this PR merges — a self-bind that breaks append-only immutability on merge. Rebind to immutable facts (PR number, base repo, head branch) with state accepted as open OR closed+merged, keeping the check falsifiable for a wrong PR number/branch. * fix(OMN-14888): supersede stale occ-self-bind-pr-6134 open-state assertion PR #6134 merged (2026-08-09T03:14:53Z, merge commit ea53c31...) while its merged dod_evidence entry occ-self-bind-pr-6134 still asserts .state == "open" -- the same class OMN-15374's occ-self-bind-pr-5855-superseded fixed (OCC #6084 precedent). Append a net-new superseding entry bound to the merged-terminal state; the original entry stays untouched (append-only). --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-15763): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2028 (#6242) * evidence(OMN-15763): author OCC companion for OmniNode-ai/omnimarket#2028 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 512b272bb26aba643093872519c8c46c142b0de2. * evidence(OMN-15763): self-bind OCC#6242 + rebind contract_sha256 * fix(OMN-15763): backfill missing dod-occ-evidence-admissibility-validator contract entry The OCC Companion Author automation emitted this receipt on PR #2028's companion (dod-occ-evidence-admissibility-validator, node_pr_lifecycle_fix_effect self-check) without adding the matching dod_evidence contract entry, tripping the receipt-hardening append-only gate. Backfills the entry (source: generated, matching the shape of the other autobind entries) and computes the real contract_entry_sha256 via compute_contract_entry_sha256 (was a "PENDING" placeholder) — verified locally against scripts/validation/check_receipt_hardening.py. OMN-15763 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml) (#6138) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2023/cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31057101391-1 * evidence(OMN-14888): self-bind OCC observation PR 6138 * evidence(OMN-14888): make OCC self-bind 6138 append-stable * fix(OMN-14888): regenerate occ-self-bind-pr-6138 receipt for self-bind fix The self-bind entry's check_value was rewritten to bind to immutable facts (PR#/head ref/base repo, state open OR closed+merged) so the assertion survives merge, matching the #6132/#6144 precedent. This changes contract_entry_sha256, so the receipt is regenerated with the recomputed hash and a fresh live probe readback. --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml) (#6152) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2024/38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31062523818-1 * evidence(OMN-14888): self-bind OCC observation PR 6152 * evidence(OMN-14888): make OCC self-bind 6152 append-stable --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml) (#6164) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2025/d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31142195987-1 --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-15757, OMN-15778): OCC companion for OmniNode-ai/omninode_infra#833 (#6246) * evidence: OCC companion pass 1 for OmniNode-ai/omninode_infra#833 * evidence: OCC companion self-bind for #6246 --------- Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai> * evidence(OMN-15336): bind infra PR 2676 vendor migration (#6167) * evidence(OMN-15336): bind infra PR 2676 vendor migration * evidence(OMN-15336): self-bind OCC PR 6167 * evidence(OMN-15336): refresh registry RLS heads * fix(OMN-15336): supersede market PR 2021 evidence append-only * evidence(OMN-15336): rebind infra PR 2676 current head * chore(OMN-15336): retrigger OCC gates * evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2029 (#6247) * evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2029 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5. * evidence(OMN-15777): self-bind OCC#6247 + rebind contract_sha256 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> * evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2030 (#6248) * evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2030 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 271a7abe276bc6a5663599a6e7736c8faab843f7. * evidence(OMN-15777): self-bind OCC#6248 + rebind contract_sha256 * fix(OMN-15777): revert unintended mutation of merged receipt (append-only repair) The occ-evidence-source-autobind commit for PR #2030 (57e1628) rebound drift/dod_receipts/OMN-15777/dod-occ-evidence-admissibility-validator/command.yaml in place -- but that receipt already merged as part of OCC#6247 (PR #2029's companion) and is immutable per the append-only doctrine. PR #2030 already carries its own dedicated, net-new evidence entries (dod-OmniNode-ai-omnimarket-pr-2030, dod-OmniNode-ai-omnimarket-pr-2030-ci, occ-self-bind-pr-6248) that bind it to commit 271a7abe; the shared validator receipt did not need to be re-pointed at PR #2030 to satisfy that binding. Reverts the file to its merged-on-dev content. No supersession file is needed -- this is not a correction to the receipt's claim (still true and still bound to PR #2029/commit f9cc9dcc), it is an unforced touch that should never have modified it. Implements OMN-15777 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-15780): OCC Evidence-Source autobind for OmniNode-ai/omninode_infra#834 (#6250) * evidence(OMN-15780): author OCC companion for OmniNode-ai/omninode_infra#834 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 1fdeb0c9c9367d70e43ef88b128203cf567c4aed. * evidence(OMN-15780): self-bind OCC#6250 + rebind contract_sha256 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> * evidence(OMN-14888): OCC observation append (023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml) (#6155) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31063872175-1 * evidence(OMN-14888): self-bind OCC observation PR 6155 * evidence(OMN-14888): make OCC self-bind 6155 append-stable * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5__v1__run31303503673-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31303503673-1 * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/c11400fe9483b9face2601c391f0a73add5d52cf__v1__run31304580306-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31304580306-1 * fix(OMN-14888): repair occ-self-bind-pr-6155 receipt after dev-merge Conflict resolution against dev landing on PR #6155 rewrote the occ-self-bind-pr-6155 dod_evidence entry's check_value to accept the terminal closed+merged PR state (matching the occ-self-bind-pr-6134 / occ-self-bind-pr-6149 established pattern) instead of a bare .state == "open" assertion that would fail closed the moment this PR merges. That byte change moved the per-entry contract hash, so the paired receipt is regenerated here with the recomputed contract_entry_sha256 and a fresh live probe_stdout. --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml) (#6237) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31291311120-1 --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (2cea83b3d664a5a3a919d4e14994a03a479ac90f__v1__run31292255084-1.yaml) (#6240) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/2cea83b3d664a5a3a919d4e14994a03a479ac90f__v1__run31292255084-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31292255084-1 * evidence(OMN-15763): OCC companion for omnimarket PR #2027 (#6239) * evidence(OMN-15763): OCC companion for omnimarket PR #2027 Falsifiable deploy-gate evidence (OMN-14505 sense) for the seam registry + canonical seam-projection serialization PR: three live GitHub-content probes against the PR head commit (canonical.py's canonical_sha256, node_seam_match_compute's HandlerSeamMatch, and seams.v1.yaml's schema_version header), plus the standard self-bind check. All three probes verified locally against the PR head SHA 6bbd87de3c0173956969f5a0b159c8631e4b929e before committing. Rebuilt on origin/dev (onex_change_control's live default branch — main now accepts only promotion/hotfix PRs, discovered live via main-target-guard on the first attempt against main). Net-new-file-only. OMN-15763 * fix(OMN-15763): buffer check_value producers to avoid Rule E SIGPIPE false-RED OMN-15411 Rule E (contract corpus ratchet) caught 3 new sigpipe-fragile instances: gh api <contents> --jq .content | base64 -d | grep -q ... is a measured SIGPIPE-fragile shape (141/0/141/0/141 across 5 runs against real inputs) — grep -q exits at the first match and closes its stdin, base64 -d is killed by SIGPIPE, and dod_verify's bash -o pipefail turns that 141 into a false RED on evidence that is actually present. Rewrote all three live-content probes to the buffered-read form: body="$(<producer>)" && printf '%s' "$body" | grep -qF 'MARKER'. Verified locally: sigpipe_fragile_violation() returns None for all three (was non-None before), all three still execute correctly under bash -o pipefail -c against the live GitHub API, and validate_pr_deploy_required.has_deploy_evidence() still returns True (the buffered form still classifies as a falsifiable live-surface probe). Also re-pinned all three refs to the omnimarket PR's final head commit f1741be0163ab757738bb9ddbf7d2d67aca6aa49 (was 6bbd87de, superseded by the CodeRabbit-fix commit). OMN-15763 * evidence(OMN-15763): PASS receipts for all four dod_evidence items occ-preflight/verify hard-required receipts under drift/dod_receipts/OMN-15763/<item_id>/command.yaml for every item -- an OCC PR's in-tree contract carries its own receipts (the "in-repo trap"). All four probes run for real against the omnimarket PR #2027 head commit f1741be0163ab757738bb9ddbf7d2d67aca6aa49 and this OCC PR's own state (#6239). contract_sha256 + contract_entry_sha256 computed via omnibase_core.validation.validator_receipt_gate against the landed contract (commit 5f647f0). Verified locally end-to-end: uv run python -m omnibase_core.validation.validator_occ_merge_eligibility against this tree returns eligible=true, reason=eligible, zero missing_or_nonpass_receipts. probe_stdout required a non-empty value (ModelDodReceipt: "receipts with empty stdout are indistinguishable from probes that never ran") -- the contract's check_value stays the buffered grep -qF form (Rule E safe, quiet by design), while each receipt's own probe_command is the non-quiet grep -F variant that captures the actual matched line as real evidence. OMN-15763 * evidence(OMN-14888): OCC observation append (b8a1eb65a20f32e0e00efd473aaf7b69f3cad6f9__v1__run31058937953-1.yaml) (#6144) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/b8a1eb65a20f32e0e00efd473aaf7b69f3cad6f9__v1__run31058937953-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31058937953-1 * evidence(OMN-14888): self-bind OCC observation PR 6144 * evidence(OMN-14888): make OCC self-bind 6144 append-stable * fix(OMN-14888): repair self-bind assertion in occ-self-bind-pr-6144 Rewrite the dod_evidence check to bind PR #6144 to immutable facts (PR number, base repo, exact head ref) and accept state open OR closed+merged, so the check stays true after this PR merges instead of asserting .state == "open" forever. * fix(OMN-14888): regenerate occ-self-bind-pr-6144 receipt for repaired check_value Bind contract_entry_sha256 to the updated dod_evidence entry hash so the OCC merge-eligibility gate's per-entry binding check passes. * fix(OMN-14888): supersede occ-self-bind-pr-6134 with merged-terminal-state binding PR #6134 merged to dev (2026-08-09T03:14:53Z, ea53c31) while this PR was in flight. Its self-bind entry asserts .state == "open" forever, which now fails closed. Append-only supersession per the occ-self-bind-pr-5855-superseded / occ-self-bind-pr-6149-superseded precedent — bind to the merged-terminal state instead; the superseded entry stays verbatim for audit. --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (7bd1c1a9c39823834fe4e38dabc785887ecf524c__v1__run31054912492-1.yaml) (#6132) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2021/7bd1c1a9c39823834fe4e38dabc785887ecf524c__v1__run31054912492-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31054912492-1 * evidence(OMN-14888): self-bind OCC observation PR 6132 * evidence(OMN-14888): make OCC self-bind 6132 append-stable * fix(OMN-14888): regenerate occ-self-bind-pr-6132 receipt for entry-hash match The contract entry's check_value was rewritten to accept open OR closed+merged terminal state (self-bind fix), which changed its recomputed contract_entry_sha256. Regenerated the receipt with a fresh live probe against PR #6132 and the matching entry hash so occ-preflight eligibility passes instead of failing on contract_hash_mismatch. --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * fix(OMN-15722): raise starved guard-job timeout budgets in OCC ci.yml (#6173) * fix(OMN-15722): raise starved guard-job timeout budgets in OCC ci.yml Five guard jobs carry timeout-minutes budgets below the observed latency of the self-hosted omnibase-ci runner fleet under concurrent load. When a job hits its own timeout wall GitHub records conclusion=cancelled, and CI Summary (the sole required umbrella context on onex_change_control dev) compares each needs.<job>.result against "success" fail-closed - so a guard that passed gets scored as a violation and turns the required context red. Raise the three 5-minute guards and the two 10-minute jobs to 20 minutes: - validate-prod-promotion-grants 5 -> 20 - check-platform-leads-review-tripwire 5 -> 20 - check-bot-authored-authz-guard 5 -> 20 - predicate-parity 10 -> 20 - no-noncanonical-lifecycle-classes 10 -> 20 Not a gate weakening: every guard still runs, still must reach conclusion=success, and CI Summary's fail-closed != "success" comparison is untouched. Only the wall-clock budget moved. Evidence-Ticket: OMN-15722 * evidence(OMN-15722): add OCC ticket contract + PASS receipts for guard timeout fix The first push carried no contracts/OMN-15722.yaml, so both of the two content-gating required contexts on this PR failed with the same single root cause: validator_occ_merge_eligibility reported reason=missing_contract / missing_contracts=["OMN-15722"] on `occ-preflight / eligibility` (job 93010633789) and on `verify / verify` step 21 "Run OCC Eligibility" (job 93010633875). Note step 7 "Resolve Evidence-Source" was SKIPPED in that same job, confirming the in-repo Evidence-Source exemption - the missing contract was the only blocker. Contract declares three dod_evidence items, all probed live and receipted with real command output (no fabricated receipts): dod-occ-guard-timeout-budgets-raised - substantive (L1): parses ci.yml and asserts all five named guard jobs declare timeout-minutes 20. dod-occ-guards-still-fail-closed - substantive (L1): asserts all five guards remain in ci-summary's needs list, carry no continue-on-error, still have their literal fail-closed `result }}" != "success"` comparison in ci.yml, and that ci.yml still declares no top-level concurrency block. Falsifiability proven by negative control - rewriting the predicate-parity comparison to an equality form makes the same probe exit 1 with unguarded=['predicate-parity']. occ-self-bind-pr-6173 - binding stamp only (L0), companion PR identity for receipt-gate binding. Local verification: all three probes exit 0 / stdout "true"; the eligibility validator now returns eligible=true reason=eligible ("OCC evidence is present, PASS, hash-bound, and PR-bound") with all three receipt ids resolved. Full pre-commit over contract + receipts + ci.yml passes, including Receipt Honesty Gate, Receipt Hardening Gate, Contract Substance Floor, DoD-authoring hygiene, Canonical contract shape v1, and the Evidence-Commit SHA Existence Gate. Evidence-Ticket: OMN-15722 * evidence(OMN-15722): remove false no_source_change attestation from receipts All three OMN-15722 receipts asserted no_source_change: true. Per omnibase_core model_dod_receipt.py that field is RUNTIME_OPS-only and asserts the change produced NO repo diff and NO PR. This change has a 5-line ci.yml diff and IS PR #6173, so the assertion was materially false. These receipts carry evidence_class: None and pr_number: 6173, so the field does not apply to them at all -- removed rather than set to false. Its default is False, which is the truthful value. All three re-validate against ModelDodReceipt with no_source_change=False. Note: the model validator enforces only the RUNTIME_OPS -> True direction, not the inverse, so a non-RUNTIME_OPS receipt asserting no_source_change: true alongside a pr_number validates cleanly and no CI gate would have caught this. Model gap, flagged not fixed here. * fix(OMN-15722): widen validate-prod-promotion-grants budget to 45m (19m02s measured) The 20m budget left that job ~58s of headroom against its measured 19m02s runtime on PR #6173 run 31222755192 — a re-starve one contention spike away, which is the exact defect this PR exists to remove. Profile of the 19m02s (steps API, head 2df62fc): Checkout code 11m48s Run ./.github/actions/setup-uv 5m30s Validate prod-promotion-grants trust anchor 2s The work is 2 seconds; the runtime is fleet latency. Within that one run, Checkout code for the same repo/SHA ranged 74s (omninode-runner-63) to 708s (omninode-runner-21) — a ~9.6x contention spread — so the budget must cover the latency tail, not the job's work. 45m is ~2.4x the worst observation. Other four guards unchanged at 20. Contract probe updated from a flat ==20 assertion to a per-job expected-budget map so it stays falsifiable, and the contract summary corrected (it claimed all five go to 20). * evidence(OMN-15722): re-stamp all three receipts at head d772fb8 The prior stamps carried run_timestamp 2026-08-07T22:29:26Z / commit_sha 2df62fc, which predated both the 45m widening and the contract edit — the receipts attested a tree that no longer existed. All three probes were re-run against the working tree at d772fb8; none of these values is carried over: dod-occ-guard-timeout-budgets-raised exit 0, stdout 'true' dod-occ-guards-still-fail-closed exit 0, stdout 'true' occ-self-bind-pr-6173 exit 0, stdout 'true' Receipt 1's probe changed with the contract: a flat 'all five == 20' assertion would now fail, so it became a per-job expected-budget map (45/20/20/20/20). Its contract_entry_sha256 is recomputed to sha256:4c1ae3b62a7def4f0ca209d9921d974c6c74a4927cb8dc5fa3d4e32a99adeec8; entries 2 and 3 are parse-identical so their hashes are unchanged. Both substantive probes re-verified falsifiable at this head by negative control — reverting 45->20 exits 1 with [('validate-prod-promotion-grants', 20, 45)], and flipping the predicate-parity comparison to == exits 1 with unguarded=['predicate-parity']. * fix(OMN-15722): uniform 45m timeout floor across all 10 budgeted ci-summary needs members contract-shape-v1 (budget 25) was cancelled at 25m50s on this PR's own run 31222755192, cancelled step Checkout code (1358s) - the same starvation the five already-raised guards hit. Inside that one run, for the same repo and SHA, checkout ranged 6s-1358s and setup-uv 93s-571s, so the runner preamble alone has been observed above 30m and every per-job budget under that is provably insufficient. Sets 45 uniformly across all ten ci-summary needs members that declare a timeout-minutes. Also corrects the inline fleet-size comment: live gh api orgs/OmniNode-ai/actions/runners reports 64 runners labelled omnibase-ci, not 48. * evidence(OMN-15722): re-stamp all three receipts at the uniform-45m head * docs(OMN-15722): tighten the latency claim to single-phase observations The prior wording said the runner preamble had been observed above 30m; that number was a cross-job sum of the worst checkout (1358s, contract-shape-v1) and the worst setup-uv (571s, a different job), not a single observed preamble. Replaced with the two exact single-phase observations plus the worst own-work step among the ten budgeted gates (53s). No budget changes. * evidence(OMN-15722): re-stamp all three receipts at 63be7d6 * evidence(OMN-15722): admissible self-bind supersedes gh-pr-view INERT check occ-self-bind-pr-6173 uses `gh pr view`, which lexes to bare `gh` in command position (not `gh api`) and is INADMISSIBLE (NOT_EXECUTED) under the OMN-15309 evidence_admissibility predicate. Contract Compliance Check on this PR's own run (31228584791, job 93027660648) collapsed the whole dod_evidence supersession chain to 0/3 PASS -> BLOCK, reddening the required check. Append-only fix: occ-self-bind-pr-6173-admissible supersedes it with `gh api repos/OWNER/REPO/pulls/6173/files` asserting the changed-file count (5), with printed stdout so the run is distinguishable from a probe that never executed (Receipt Hardening Gate, OMN-13060/OMN-15710). Verified ADMISSIBLE by direct execution of classify_evidence over the exact check_value, and the check itself run green (count=5) and red (count=4, exit 1) before being recorded. Nothing above the new entries in contracts/OMN-15722.yaml is edited; every prior dod_evidence item keeps its bytes and OMN-13888 per-entry hash. Local run of scripts/ci/run_contract_compliance_check.py against this head confirms PASS (1/4 PASS, 3 WARN, 0 BLOCK). * evidence(OMN-15722): correct stale self-bind file-count assertion (5 -> 7) occ-self-bind-pr-6173-admissible asserted PR #6173's changed-file count == 5, but adding its own receipt file to the diff made the live count 6 the moment it was committed -- confirmed red on Contract Compliance Check (job 93048702548, run 31236076328): live count=6, assertion expected 5, exit 1. Appends occ-self-bind-pr-6173-admissible-v2, a self-inclusive correction: its own receipt file is the 7th changed path, so it asserts count == 7, the number that includes the file recording its own PASS. * evidence(OMN-15722): OCC companion for #6173 (#6174) * evidence: OCC companion pass 1 for #6173 * evidence: OCC companion self-bind for #6174 * fix(OMN-15722): format OCC autobind contract --------- Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml) (#6149) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/d72b0c37559ddb1bad988e5a0f0a4c6011f0eb85__v1__run31061495853-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31061495853-1 * evidence(OMN-14888): self-bind OCC observation PR 6149 * evidence(OMN-14888): make OCC self-bind 6149 append-stable * fix(OMN-14888): repair PR #6149 self-bind to append-only-stable predicate The occ-self-bind-pr-6149 dod_evidence entry asserted .state == "open", which goes false the instant this PR merges — a self-bind that breaks append-only immutability on merge. Rebind to immutable facts (PR number, base repo, head branch) with state accepted as open OR closed+merged, keeping the check falsifiable for a wrong PR number/branch. * fix(OMN-14888): supersede stale occ-self-bind-pr-6134 open-state assertion PR #6134 merged (2026-08-09T03:14:53Z, merge commit ea53c31...) while its merged dod_evidence entry occ-self-bind-pr-6134 still asserts .state == "open" -- the same class OMN-15374's occ-self-bind-pr-5855-superseded fixed (OCC #6084 precedent). Append a net-new superseding entry bound to the merged-terminal state; the original entry stays untouched (append-only). --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-15763): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2028 (#6242) * evidence(OMN-15763): author OCC companion for OmniNode-ai/omnimarket#2028 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 512b272bb26aba643093872519c8c46c142b0de2. * evidence(OMN-15763): self-bind OCC#6242 + rebind contract_sha256 * fix(OMN-15763): backfill missing dod-occ-evidence-admissibility-validator contract entry The OCC Companion Author automation emitted this receipt on PR #2028's companion (dod-occ-evidence-admissibility-validator, node_pr_lifecycle_fix_effect self-check) without adding the matching dod_evidence contract entry, tripping the receipt-hardening append-only gate. Backfills the entry (source: generated, matching the shape of the other autobind entries) and computes the real contract_entry_sha256 via compute_contract_entry_sha256 (was a "PENDING" placeholder) — verified locally against scripts/validation/check_receipt_hardening.py. OMN-15763 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml) (#6138) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2023/cf77a700703ded2f8c99eacfb7695bdd767f772f__v1__run31057101391-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31057101391-1 * evidence(OMN-14888): self-bind OCC observation PR 6138 * evidence(OMN-14888): make OCC self-bind 6138 append-stable * fix(OMN-14888): regenerate occ-self-bind-pr-6138 receipt for self-bind fix The self-bind entry's check_value was rewritten to bind to immutable facts (PR#/head ref/base repo, state open OR closed+merged) so the assertion survives merge, matching the #6132/#6144 precedent. This changes contract_entry_sha256, so the receipt is regenerated with the recomputed hash and a fresh live probe readback. --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml) (#6152) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2024/38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31062523818-1 * evidence(OMN-14888): self-bind OCC observation PR 6152 * evidence(OMN-14888): make OCC self-bind 6152 append-stable --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml) (#6164) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2025/d0a4ff2ed7aa85267dd8b9013cf8a0782418d951__v1__run31142195987-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31142195987-1 --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-15757, OMN-15778): OCC companion for OmniNode-ai/omninode_infra#833 (#6246) * evidence: OCC companion pass 1 for OmniNode-ai/omninode_infra#833 * evidence: OCC companion self-bind for #6246 --------- Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai> * evidence(OMN-15336): bind infra PR 2676 vendor migration (#6167) * evidence(OMN-15336): bind infra PR 2676 vendor migration * evidence(OMN-15336): self-bind OCC PR 6167 * evidence(OMN-15336): refresh registry RLS heads * fix(OMN-15336): supersede market PR 2021 evidence append-only * evidence(OMN-15336): rebind infra PR 2676 current head * chore(OMN-15336): retrigger OCC gates * evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2029 (#6247) * evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2029 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5. * evidence(OMN-15777): self-bind OCC#6247 + rebind contract_sha256 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> * evidence(OMN-15777): OCC Evidence-Source autobind for OmniNode-ai/omnimarket#2030 (#6248) * evidence(OMN-15777): author OCC companion for OmniNode-ai/omnimarket#2030 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 271a7abe276bc6a5663599a6e7736c8faab843f7. * evidence(OMN-15777): self-bind OCC#6248 + rebind contract_sha256 * fix(OMN-15777): revert unintended mutation of merged receipt (append-only repair) The occ-evidence-source-autobind commit for PR #2030 (57e1628) rebound drift/dod_receipts/OMN-15777/dod-occ-evidence-admissibility-validator/command.yaml in place -- but that receipt already merged as part of OCC#6247 (PR #2029's companion) and is immutable per the append-only doctrine. PR #2030 already carries its own dedicated, net-new evidence entries (dod-OmniNode-ai-omnimarket-pr-2030, dod-OmniNode-ai-omnimarket-pr-2030-ci, occ-self-bind-pr-6248) that bind it to commit 271a7abe; the shared validator receipt did not need to be re-pointed at PR #2030 to satisfy that binding. Reverts the file to its merged-on-dev content. No supersession file is needed -- this is not a correction to the receipt's claim (still true and still bound to PR #2029/commit f9cc9dcc), it is an unforced touch that should never have modified it. Implements OMN-15777 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-15780): OCC Evidence-Source autobind for OmniNode-ai/omninode_infra#834 (#6250) * evidence(OMN-15780): author OCC companion for OmniNode-ai/omninode_infra#834 OCC companion by node_pr_lifecycle_fix_effect (OMN-13317 F1 / OMN-13990 / OMN-14285). Product PR head 1fdeb0c9c9367d70e43ef88b128203cf567c4aed. * evidence(OMN-15780): self-bind OCC#6250 + rebind contract_sha256 --------- Co-authored-by: omnimarket-bot <bot@omninode.ai> * evidence(OMN-14888): OCC observation append (023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml) (#6155) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2022/023992b513456767c2ee39ad35703246bca5d83e__v1__run31063872175-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31063872175-1 * evidence(OMN-14888): self-bind OCC observation PR 6155 * evidence(OMN-14888): make OCC self-bind 6155 append-stable * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/f9cc9dcc1eddb67bb5acba9247677b1ab3f3e9f5__v1__run31303503673-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31303503673-1 * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2029/c11400fe9483b9face2601c391f0a73add5d52cf__v1__run31304580306-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31304580306-1 * fix(OMN-14888): repair occ-self-bind-pr-6155 receipt after dev-merge Conflict resolution against dev landing on PR #6155 rewrote the occ-self-bind-pr-6155 dod_evidence entry's check_value to accept the terminal closed+merged PR state (matching the occ-self-bind-pr-6134 / occ-self-bind-pr-6149 established pattern) instead of a bare .state == "open" assertion that would fail closed the moment this PR merges. That byte change moved the per-entry contract hash, so the paired receipt is regenerated here with the recomputed contract_entry_sha256 and a fresh live probe_stdout. --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> * evidence(OMN-14888): OCC observation append (6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml) (#6237) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/6bbd87de3c0173956969f5a0b159c8631e4b929e__v1__run31291311120-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31291311120-1 --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> Co-authored-by: onexbot-occ-writer[bot] <307849072+onexbot-occ-writer[bot]@users.noreply.github.com> Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai> Co-authored-by: omnimarket-bot <bot@omninode.ai> * evidence(OMN-14888): OCC observation append (f1741be0163ab757738bb9ddbf7d2d67aca6aa49__v1__run31293106241-1.yaml) (#6241) * evidence(OMN-14888): OCC observation append drift/occ_observations/OmniNode-ai__omnimarket/pr-2027/f1741be0163ab757738bb9ddbf7d2d67aca6aa49__v1__run31293106241-1.yaml * evidence(OMN-14888): OCC observation self-bind occ-observation-run31293106241-1 --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> --------- Co-authored-by: node-occ-observation-effect <occ-observation-effect@omninode.ai> Co-authored-by: onexbot-occ-writer[bot] <307849072+onexbot-occ-writer[bot]@users.noreply.github.com> Co-authored-by: node-occ-companion-effect <occ-companion-effect@omninode.ai> Co-authored-by: Jonah Gray <jonah@omninode.ai> Co-authored-by: omnimarket-bot <bot@omninode.ai>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Deterministic, append-only OCC observation record authored by node_occ_observation_effect. Adds exactly one net-new file:
drift/occ_observations/OmniNode-ai__omnimarket/pr-2024/38d1a7242b189f4d2a4b20e5324ce8f3f13f3be8__v1__run31062523818-1.yaml.Implements OMN-14888
Evidence-Ticket: OMN-14888